YeniInformation technology

Cybersecurity GRC Specialist

Ninja

Riyadh4h ago

Şimdi başvur

Rol hakkında

The Cybersecurity GRC Specialist will support cybersecurity governance, risk, and compliance activities across the Group. The role will focus on maintaining cybersecurity policies and controls, coordinating risk assessments and compliance evidence, tracking remediation actions, and supporting regulatory, audit, and assurance activities.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Risk Management, Business Administration, or a related field.
  • 2–4 years of experience in cybersecurity GRC, information security, risk, compliance, or a related function.
  • Good understanding of cybersecurity governance, risk assessment, control testing, and compliance.
  • Familiarity with Saudi cybersecurity requirements and information security frameworks.
  • Strong documentation, analytical, and stakeholder coordination skills.
  • Ability to communicate effectively with both technical and non-technical stakeholders.
  • Professional proficiency in Arabic and English.
  • Certifications such as ISO 27001, CRISC, CISA, CGRC, or equivalent are preferred.

Key Responsibilities

  • Support the development and maintenance of cybersecurity policies, standards, procedures, and governance records.
  • Coordinate cybersecurity risk assessments for systems, projects, suppliers, and business initiatives.
  • Maintain risk registers, track treatment plans, and follow up on overdue actions.
  • Support cybersecurity compliance assessments against regulatory and internal requirements.
  • Coordinate the collection, validation, and organization of compliance and audit evidence.
  • Support Internal Audit, external assessments, and regulatory reviews by preparing required cybersecurity evidence.
  • Track audit findings, remediation actions, and closure evidence.
  • Support cybersecurity due diligence and risk reviews for third parties and service providers.
  • Maintain security exceptions, risk acceptance records, and required follow-ups.
  • Prepare GRC reports, dashboards, and management updates.
  • Identify control gaps and opportunities to improve cybersecurity governance processes.

Kaynak: işverenin kendi kariyer sayfası.

Benzer işler